ZeroHour

Vulnerabilities

21 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-5200
The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insuffic

The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • flowpaper flowpaper
CVE-2023-40197
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions.

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Devaldi Ltd flowpaper plugin <= 1.9.9 versions.

NVD description · AI analysis pending
5.4<1%
  • flowpaper flowpaper
CVE-2020-23878
+1 in the same advisory: …23879
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.

pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.

NVD description · AI analysis pending
9.8
group max
2% PoC ×2
  • flowpaper pdf2json
CVE-2020-19464
An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow .

NVD description · AI analysis pending
5.5<1% PoC
  • flowpaper pdf2json
CVE-2020-18750
Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.

Buffer overflow in pdf2json 0.69 allows local users to execute arbitrary code by converting a crafted PDF file.

NVD description · AI analysis pending
7.8<1% PoC
  • flowpaper pdf2json
CVE-2018-11686
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

NVD description · AI analysis pending
9.853% PoC
  • flowpaper flexpaper
CVE-2018-14947
+1 in the same advisory: …14946
An issue has been found in PDF2JSON 0.69.

An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).

NVD description · AI analysis pending
8.82% PoC ×2
  • flowpaper pdf2json